Skip to content

Add --authmode to setup all: control agent identity permission grants (OBO/S2S/both) - #391

Merged
Sellakumaran Kanagarathnam (sellakumaran) merged 6 commits into
mainfrom
users/sellak/setup-authtype
Apr 29, 2026
Merged

Sellakumaran Kanagarathnam (sellakumaran) merged 6 commits into
mainfrom
users/sellak/setup-authtype

Conversation

@sellakumaran

Copy link
Copy Markdown
Contributor

Summary

Introduce --authmode (obo|s2s|both) to a365 setup all, giving users control over how the agent identity service principal receives permissions:

  • obo (default): principal-scoped delegated grants — no Global Admin required
  • s2s: app role assignments on the agent identity SP — attempted programmatically, PowerShell fallback if caller lacks Global Admin
  • both: applies OBO delegated grants and S2S app role assignments

For non-AI Teammate agents, inheritable permissions and AllPrincipals grants (Phase 2a/2b) are always skipped regardless of authMode.

Changes

  • setup all: new --authmode option; validated against --aiteammate (mutually exclusive)
  • NonDwBlueprintSetupOrchestrator: applies delegated grants, app role assignments, or both; S2S PowerShell fallback prints only for specs that actually failed
  • SetupHelpers: dry-run plan and live summary updated to reflect authMode; messaging endpoint messages cleaned up
  • Agent365Config: new authMode init-only property — persists across runs when set in a365.config.json
  • GraphApiService: treats "Permission entry already exists" as success — grants are idempotent on re-run
  • Dead --authmode code removed from setup blueprint and setup permissions (no agent identity grant step in those commands)
  • Docs updated: README.md, design.md, Models/README.md, CHANGELOG.md

Test Plan

  • --authmode obo dry-run: step 3 skipped, step 5 shows delegated grants only
  • --authmode s2s dry-run: step 3 skipped, step 5 shows app perms only
  • --authmode both dry-run: step 5 shows both rows
  • --authmode + --aiteammate returns exit code 1 with explanatory error
  • Invalid --authmode value returns exit code 1
  • Omitting --authmode defaults to OBO behavior (delegated grants present, S2S absent)
  • Live OBO run: portal shows User consent tab, token has scp: Agent365.Observability.OtelWrite
  • 1310 unit tests passing

Introduce --authmode (obo|s2s|both) to a365 setup all and related flows, allowing users to control how agent identity permissions are granted. For non-DW agents, inheritable permissions and AllPrincipals grants are always skipped to avoid requiring Global Admin. The orchestrator now applies delegated grants, app role assignments, or both based on authMode, with PowerShell fallback for S2S if needed. The dry-run plan and summary output reflect these changes. Agent365Config and docs updated to support authMode. Includes extensive tests for all authMode values and validation logic. GraphApiService now treats "Permission entry already exists" as success.
- Dry-run no longer detects tenant ID via az CLI when not needed.
- "Inheritable Permissions" now shows "skipped (permissions set directly on agent identity)" for non-AI Teammate agents.
- Messaging endpoint step output clarified to "skipped (non-M365 agent)".
- Improved error message for --authmode with --aiteammate.
- Tests updated for new output and error messages.
- Changelog updated to reflect these changes.
Copilot AI review requested due to automatic review settings April 28, 2026 18:55
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Apr 28, 2026
@github-actions

github-actions Bot commented Apr 28, 2026 •

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds an --authmode (obo|s2s|both) option to a365 setup all to control whether non-DW blueprint agents receive permissions via delegated (OBO), app-role (S2S), or both, and updates dry-run/summary output and docs accordingly.

Changes:

  • Introduces --authmode on setup all and threads the resolved mode through SetupContext and the non-DW setup orchestrator.
  • Updates non-DW dry-run plan + setup summary wording to reflect “permissions set directly on agent identity” and to avoid implying inheritable permissions/admin consent for non-DW flows.
  • Makes OAuth2 grant creation more idempotent by treating “Permission entry already exists” as success; updates tests/docs/changelog.

Reviewed changes

Copilot reviewed 12 out of 12 changed files in this pull request and generated 8 comments.

Show a summary per file
File Description
src/Tests/Microsoft.Agents.A365.DevTools.Cli.Tests/Commands/SetupCommandTests.cs Adds CLI-level --authmode validation tests.
src/Tests/Microsoft.Agents.A365.DevTools.Cli.Tests/Commands/NonDwBlueprintSetupOrchestratorDryRunTests.cs Updates and adds dry-run assertions for authMode behavior.
src/Microsoft.Agents.A365.DevTools.Cli/design.md Documents authMode as a persisted config field.
src/Microsoft.Agents.A365.DevTools.Cli/Services/GraphApiService.cs Treats “Permission entry already exists” as idempotent success for oauth2 grants.
src/Microsoft.Agents.A365.DevTools.Cli/Models/README.md Documents AuthMode on Agent365Config.
src/Microsoft.Agents.A365.DevTools.Cli/Models/Agent365Config.cs Adds AuthMode property and carries it through cloning helpers.
src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupHelpers.cs Adjusts setup summary logic and messaging endpoint “skipped” text.
src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupContext.cs Adds AuthMode + helper booleans for gating OBO/S2S steps.
src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/README.md Adds authMode documentation (currently overstates command availability).
src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/NonDwBlueprintSetupOrchestrator.cs Reworks non-DW plan/execution to skip Phase 2a/2b and apply grants to agent identity per authMode (with PS fallback for S2S).
src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/AllSubcommand.cs Adds --authmode option, validation, and wiring into dry-run and execution context.
CHANGELOG.md Adds release notes for --authmode and related dry-run/summary fixes.

Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/README.md Outdated
Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Models/Agent365Config.cs
Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupHelpers.cs Outdated
Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupContext.cs Outdated
- Enforces allowed values for authMode in config and CLI, with
  normalization to prevent silent misconfigurations.
- Adds admin prompt for missing CLI app: Global Admins can create and
  consent or enter an existing ID; non-admins prompted for ID only.
- Implements CreateCliClientAppAsync for app/SP creation and admin
  consent grant, with isFallbackPublicClient and WAM redirect URI set
  at creation time.
- Reverts WellKnownClientAppDisplayName to "Agent 365 CLI" (was left
  as personal test value "Agent 365 CLISellak").
- Prevents duplicate admin action rows in S2S summary output.
- Expands test coverage for all new flows; stubs GraphPatchAsync to
  eliminate real subprocess call in CreateCliClientAppAsync test.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 16 out of 16 changed files in this pull request and generated 3 comments.

Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupHelpers.cs Outdated
Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Services/GraphApiService.cs Outdated
Refactor setup summary to accurately reflect S2S app role assignment and delegated grant status, preventing duplicate or misleading "Action Required" rows. Reorder non-DW agent steps to match dry-run order. Add error logging for failed redirect URI patching after app registration. Add unit tests for S2S app role assignment scenarios. Update changelog to clarify Global Admin flows and summarize these improvements.
ajmfehr
ajmfehr previously approved these changes Apr 28, 2026
- Switch blueprint SP creation to /serviceprincipals/graph.agentIdentityBlueprintPrincipal per MSFT guidance
- Revise admin consent instructions: Option A (Entra portal) now covers only delegated permissions; application permissions for agent identity must be granted via PowerShell (Option B)
- Remove step 7 from Option A and add note redirecting to PowerShell
- Update PowerShell instructions to use agent identity SP object ID and assign app roles only to agent identity in non-DW flows
- Add AgentIdentity.Read.All to required permissions and clarify Application.ReadWrite.All is not needed for blueprint creation
- Change agent registrations endpoint to /beta/copilot/agentRegistrations
- Update unit tests to match new consent flow and permission requirements
- Aligns with latest Agent ID team guidance for correct admin consent and permission assignment

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 22 out of 22 changed files in this pull request and generated 4 comments.

Comment thread src/Microsoft.Agents.A365.DevTools.Cli/Commands/SetupSubcommands/SetupHelpers.cs Outdated
- Treat AgenticAppId as the SP object ID directly, removing the need for appId-to-SP lookup in non-DW flows.
- Track and report the effective auth mode ("obo", "s2s", "both") in setup results for more accurate permission grant summaries.
- Enhance PowerShell instructions: add 'Directory.Read.All' scope and optionally display agent identity SP display name.
- Refine summary logic to distinguish between full, partial, and pending permission grants, especially in "both" mode.
- Add EffectiveAuthMode property to SetupResults.
- Update tests to reflect new SP object ID handling and clarify test intent.
- Improves correctness, clarity, and user feedback for S2S and delegated grant scenarios.
@sellakumaran
Sellakumaran Kanagarathnam (sellakumaran) merged commit a8765b2 into main Apr 29, 2026
9 checks passed
@sellakumaran
Sellakumaran Kanagarathnam (sellakumaran) deleted the users/sellak/setup-authtype branch April 29, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants